Merge pull request #1 from vernonkeenan/ci/first-ci-gitleaks

ci: first-ever build/vet/test + gitleaks CI (ADR-KV-014)
pull/2/head
Vernon Keenan 2026-07-11 23:00:40 -07:00 committed by GitHub
commit 48d3f6a97a
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 71 additions and 0 deletions

51
.github/workflows/push.yml vendored Normal file
View File

@ -0,0 +1,51 @@
name: CI (lib)
# First-ever CI for go/lib (ADR-KV-014). lib is publicly mirrored on
# code.tnxs.net, so every push and PR gets a build/vet/test job plus a
# gitleaks secret-scan job. lib is a Go library — no Dockerfile, no deploy.
on:
push:
branches: ['**']
pull_request:
defaults:
run:
shell: bash
# Serialize per ref. PR runs cancel superseded validations; branch pushes never cancel.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
test:
runs-on: [self-hosted, Linux]
permissions: { contents: read }
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: stable
- name: go build ./...
run: go build ./...
- name: go vet ./...
run: go vet ./...
- name: go test ./...
run: go test ./...
gitleaks:
runs-on: [self-hosted, Linux]
permissions: { contents: read }
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
- name: gitleaks detect (git history)
run: |
docker run --rm -v "$PWD:/repo" -w /repo zricethezav/gitleaks:latest \
detect --source /repo --redact -v

20
.gitleaks.toml Normal file
View File

@ -0,0 +1,20 @@
title = "gitleaks config for code.tnxs.net/vernonkeenan/lib"
[extend]
useDefault = true
# ADR-KV-014: first-ever CI gitleaks scan surfaced 6 findings, all in
# swagger-codegen-generated Kazoo API client models and the vendored
# Kazoo swagger spec. Each is an illustrative `// Example:` / `example:`
# JWT hardcoded by the generator to document the shape of an auth_token
# field — a placeholder from the vendor's public API docs, not a
# credential issued to or used by this project. Scoped narrowly to the
# four generated files that triggered, not repo-wide.
[allowlist]
description = "Generated Kazoo API client/swagger example JWTs (not real secrets)"
paths = [
'''api/kazoo/kazoo_models/get_account_descendent_response\.go''',
'''api/kazoo/kazoo_models/get_account_callflow_response\.go''',
'''api/kazoo/kazoo_models/get_account_response\.go''',
'''swagger/kazoo-telnexus\.yaml''',
]